Network Working Group H. Jorgen Internet-Draft Independent Intended status: Experimental 29 September 2026 Expires: 2 April 2027 Oracle Confidence Gating for TTTPS: G-Score, Correlation-Aware von Neumann Confidence, and AdaptiveSwitch draft-helmprotocol-confidence-02 Abstract This document specifies an optional confidence layer for the TLS TimeToken Secure Protocol (TTTPS) [TTTPS]. It defines the G-Score, a normalized entropy measure of agreement concentration; an optional correlation-aware von Neumann extension; the InsufficientKnowledge signal; and the AdaptiveSwitch state machine over TURBO and FULL. The confidence layer qualifies whether evidence justifies action. It does not replace cryptographic integrity, define a wire format, allocate a codepoint, establish source independence, or require any core TTTPS implementation to compute confidence. Changes from -01 Separates optional L4 packet-source entropy control from Confidence G-Score, von Neumann entropy, and Epi-Entropy; prohibits packet- controller output from driving AdaptiveSwitch or PolicyEvaluator state. Clarifies that an XDP_DROP occurs before TTTPS admission and creates no TTTPS disposition or receipt. Records the source, mock- test, operator-report, and live-load evidence boundaries without claiming DDoS test results. Status of This Memo This document is an Internet-Draft and is submitted in full conformance with BCP 78 and BCP 79. Internet- Drafts are working documents of the IETF and have no formal standing in the IETF standards process. Status of This Memo This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79. Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet- Drafts is at https://datatracker.ietf.org/drafts/current/. Jorgen Expires 2 April 2027 [Page 1] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress." This Internet-Draft will expire on 2 April 2027. Copyright Notice Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved. This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/ license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Table of Contents 1. Introduction and Scope . . . . . . . . . . . . . . . . . . . 2 2. Conventions and Terminology . . . . . . . . . . . . . . . . . 3 3. G-Score . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 4. Separation from Integrity . . . . . . . . . . . . . . . . . . 4 5. External Integrity Profile Boundary . . . . . . . . . . . . . 4 6. Evidence Snapshot and Provenance Order . . . . . . . . . . . 4 7. Optional Correlation-Aware Extension . . . . . . . . . . . . 5 8. Correlation Input Contract . . . . . . . . . . . . . . . . . 6 9. Epi-Entropy Shadow Analysis . . . . . . . . . . . . . . . . . 6 10. Epi and PolicyEvaluator Authority . . . . . . . . . . . . . . 7 11. Higher-Order Dependence Diagnostic Boundary . . . . . . . . . 7 12. InsufficientKnowledge . . . . . . . . . . . . . . . . . . . . 8 13. AdaptiveSwitch . . . . . . . . . . . . . . . . . . . . . . . 8 14. Confidence Outcomes and Composed Decision Order . . . . . . . 9 15. Evidence and Implementation Boundary . . . . . . . . . . . . 9 16. Security Considerations . . . . . . . . . . . . . . . . . . . 11 17. IANA Considerations . . . . . . . . . . . . . . . . . . . . . 12 18. Normative References . . . . . . . . . . . . . . . . . . . . 12 19. Informative References . . . . . . . . . . . . . . . . . . . 12 Author's Address . . . . . . . . . . . . . . . . . . . . . . . . 13 1. Introduction and Scope Integrity answers whether a record is admissible. Confidence answers whether the available evidence justifies acting on it. A set of valid signatures can remain diffuse, correlated, or ambiguous. Treating confidence as a restatement of integrity makes the protocol unable to preserve uncertainty. Jorgen Expires 2 April 2027 [Page 2] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 This document defines an optional extension to the TTTPS core. It defines no wire format, header, octet layout, or codepoint. It does not define the mapping from observed sources to an agreement distribution, source weighting, threshold calibration, or deployment- specific physical identity. A core implementation that never computes a confidence metric and never signals InsufficientKnowledge remains conforming to the TTTPS core. This document is an experimental companion profile, not a core conformance requirement. 2. Conventions and Terminology The key words MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, SHOULD NOT, RECOMMENDED, NOT RECOMMENDED, MAY, and OPTIONAL in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174]. Source: a reference admitted under a declared identity, freshness, and provenance policy; admission does not by itself prove physical independence. Agreement distribution: a probability distribution p over the observed sources, with p_i the share attributed to source i. G-Score: the normalized Shannon entropy of p. InsufficientKnowledge: a typed result indicating that the enabled confidence policy does not justify an oracle assertion. TURBO: the AdaptiveSwitch state with reduced generation latency or other configured acceleration. FULL: the conservative AdaptiveSwitch state and initial state. Epi evidence: optional evidence about residual ambiguity among admissible interpretations. 3. G-Score For a normalized distribution p over n declared agreement buckets, with p_i >= 0 and sum_i p_i = 1, define the normalized entropy above. The same logarithm base b MUST be used in numerator and denominator. Bucket boundaries, zero-count treatment, normalization, and the bucket-generation rule MUST be declared. Reachability or response counts MUST NOT be substituted for agreement-bucket evidence without an explicit profile mapping. For n > 1, 0 <= G(p) <= 1; a point mass has G=0 and a uniform distribution has G=1. For n=1, this document Jorgen Expires 2 April 2027 [Page 3] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 defines G=0. The bucket count n is distinct from N_eff, which counts admitted provenance groups and is used by the quorum predicate. H(p) = -sum_i p_i log_b(p_i) G(p) = H(p) / log_b(n), n > 1 G(p) = 0, n = 1 When a policy enables a G-Score threshold tau_G, a threshold crossing occurs only when G(p) > tau_G. Equality does not cross the threshold. Any HOLD or InsufficientKnowledge result still depends on the separately declared quorum, alignment, and application predicates; G alone does not establish sufficient evidence. The G-Score is a marginal concentration signal. It does not prove that source labels represent independent physical origins, and it does not prove that a valid record is true. 4. Separation from Integrity The confidence subsystem is separate from the TTTPS integrity pipeline. A node MUST NOT substitute a confidence result for integrity verification. A record that fails integrity verification is invalid regardless of G(p), and a high confidence result MUST NOT make it valid. Conversely, InsufficientKnowledge is not an integrity failure. It indicates that the source evidence did not justify the requested assertion. Implementations MUST preserve the distinction in evidence receipts and failure handling. 5. External Integrity Profile Boundary Confidence qualification begins only after the selected core and external integrity/framing checks have produced an admissible byte domain. Confidence metrics MUST NOT repair or override a failed GRG or core-integrity result. This document does not define GRG parameters, key handling, codepoints, or decoder behavior; those belong to the separately selected integrity profile. 6. Evidence Snapshot and Provenance Order A confidence evaluation SHOULD consume an immutable snapshot bound to the core-record digest, context-manifest digest when present, observation-set and correlation identifiers, observation generation, policy revision, observation window, admitted identities, provenance groups, N_eff, freshness and quorum outcomes, agreement-bucket definition and counts, normalized distribution p, alignment window/frame/units, residual-matrix or operator digest and Jorgen Expires 2 April 2027 [Page 4] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 construction revision, Epi constraint-bundle digest and revision, output metrics/statuses, AdaptiveSwitch internal state, parent- snapshot digest, implementation revision, and evidence digest. Optional or unavailable evidence MUST be represented as unavailable, not omitted in a way that implies a negative or zero value. Reuse of a snapshot for a different generation or policy MUST be rejected as stale evidence. The verifier MUST validate identities and freshness, collapse labels mapped to a shared declared provenance group, and compute the effective population N_eff before quorum, agreement distribution, correlation operator, or Epi constraints are constructed. A valid signature or additional key MUST NOT by itself increase N_eff. This rule depends on the declared provenance authority; it does not prove universal physical independence. 7. Optional Correlation-Aware Extension The G-Score is marginal and cannot detect source correlation by construction. An implementation MAY assemble an admissible density operator rho and compute: S_VN(rho) = -Tr(rho log2(rho)) When rho is diagonal under the declared representation, the correlation-aware calculation reduces to the corresponding Shannon calculation. Off-diagonal structure represents supplied pairwise correlation; it is not evidence that was absent from the input. The extension is OPTIONAL and has O(n^3) operator cost in the bounded adapter. If aligned correlation data is absent, an implementation MUST either use the Shannon arm or return an explicit unavailable state; it MUST NOT fabricate a zero-correlation assertion. The optional Epi evidence layer MAY represent a bundle of admissible states, an entropy interval, or a bounded purity-derived lower bound. It MAY reduce authority at a new commit boundary, but MUST NOT rewrite an already committed record or replace the core integrity result. A deep-space implementation may use the separate profile [DEEPSPACE]. Jorgen Expires 2 April 2027 [Page 5] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 8. Correlation Input Contract A von Neumann result is computable only when the implementation has a declared operator construction, aligned observations from a common observation window, compatible units and reference frame, a missing- sample policy, and a validated positive-semidefinite, trace-one operator. A diagonal operator MUST reduce to the corresponding Shannon entropy under the declared normalization. When aligned correlation evidence is absent or invalid, the result MUST be reported as NOT_COMPUTABLE or UNAVAILABLE. Missing data MUST NOT be replaced with zero correlation. A G-Score-only fallback MAY be used only when the selected policy permits it and MUST be labelled as such. 9. Epi-Entropy Shadow Analysis Epi-Entropy is an optional epistemic layer for cases in which a single density-operator estimate would conceal admissible alternative interpretations. It is a shadow analyzer: it may qualify a new promotion or commit decision, but it MUST NOT replace core integrity or retroactively alter an issued record. For observed constraints C = {(A_k,b_k)}, an implementation MAY define the admissible density-operator bundle: B(C) = { R | R = R^dagger, R >= 0, Tr(R) = 1, Tr(R A_k) <= b_k for every k } EpiEnt(B) = [ inf_R S_VN(R), sup_R S_VN(R) ] S_VN(R) = -Tr(R log2 R) Delta_id(B) = sup_(R,R' in B) 1/2 ||R-R'||_1 The exact lower endpoint can be computationally expensive because it is a concave minimization problem. An implementation MAY instead expose the certified purity-based bound inf_R S_VN(R) >= -log2( sup_R Tr(R^2) ) as a lower bound, never as an exact endpoint unless separately established. If B(C) is empty, the implementation MUST NOT evaluate undefined entropy endpoints. It MUST return CONSTRAINT_INCONSISTENCY or a documented degraded HOLD state. A Soft-HOLD adapter MAY introduce nonnegative slack xi and solve for the minimum declared relaxation. The slack, objective, tolerance, and resulting state MUST be recorded. Slack MUST NOT silently convert an inconsistent bundle into ACCEPT. Jorgen Expires 2 April 2027 [Page 6] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 B_xi(C): Tr(R A_k) <= b_k + xi_k, xi_k >= 0 B(C) = emptyset => State = DEGRADED_HOLD after min ||xi||_2 An EpiShadowAdapter MAY consume the existing G-Score trajectory and authenticated context residuals to construct (A_k,b_k) asynchronously. Missing TCB, OWLT, ephemeris alignment, or provenance inputs MUST be represented as unavailable context or CONSTRAINT_INCONSISTENCY; they MUST NOT be replaced with zeros or an assumed independent source. A nonzero Delta_id is not by itself proof of an attack. It is a bounded ambiguity signal. Implementations SHOULD use a configured threshold, hysteresis, and bounded recovery path. The default safe action for an unresolved threshold crossing is HOLD, not permanent quarantine. 10. Epi and PolicyEvaluator Authority The Epi analyzer is read-only: it MAY read an immutable evidence snapshot and emit an Epi interval, certified bound, ambiguity measure, or typed status. It MUST NOT mutate the core record, quorum, VN input, AdaptiveSwitch, application state, or prior receipt. A PolicyEvaluator MAY consume a current Epi status and withhold a new commit by returning HOLD; that veto is policy action, not an Epi state mutation. An empty admissible bundle denotes inconsistent constraints, not zero entropy. Malformed constraints are REJECT; missing adapter or evidence needed to construct the bundle is UNVERIFIABLE; a recoverable numerical or resource limit is HOLD or UNVERIFIABLE according to policy. If a relaxed bundle or slack is used, the output MUST be labelled degraded and MUST NOT be labelled clean or exact. An exact endpoint MUST NOT be claimed unless the selected optimization was solved with a stated certificate. A purity-derived certified lower bound MUST be labelled as a bound. Solver timeout, infeasibility, and unavailable resources MUST NOT be converted to ACCEPT. 11. Higher-Order Dependence Diagnostic Boundary The higher-order D3 diagnostic is distinct from Shannon entropy, G-Score, von Neumann entropy, and Epi-Entropy. It compares observed joint structure with a maximum-entropy structure consistent with declared pairwise marginals, under a frozen sampling window, estimator, regularisation rule, and source-dependency class. Jorgen Expires 2 April 2027 [Page 7] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 D3 is an informative shadow diagnostic, not a mandatory Confidence input, production deep-space admission gate, or automatic REJECT predicate. The companion paper reports that an absolute-value candidate missed its calibration target (R2 approximately 0.133 and 0.060), while a signed third-order synthetic calibration reported R2 of 0.994027 and 0.975254, with bootstrap lower bounds 0.991293 and 0.917285. These figures describe isolated synthetic calibration only; they do not establish universal physical collusion detection. 12. InsufficientKnowledge When confidence gating is enabled and a configured confidence predicate is not established, the node MUST signal InsufficientKnowledge or an equivalent explicitly documented state. It MUST NOT assert oracle agreement for that observation merely because a marginal concentration score is available. The final predicate is implementation-defined and MAY include diffuse agreement, missing aligned correlation, effective quorum below policy, stale physical context, or an ambiguous Epi bundle. A missing optional VN input MUST NOT be reported as a computed VN result. 13. AdaptiveSwitch AdaptiveSwitch maintains per-node operating mode in {TURBO, FULL}; this mode is not an admission disposition. The initial state MUST be FULL. Deployments define the entry threshold, maintenance threshold, evaluation window, dwell time, and backoff policy. A node MUST NOT enter TURBO unless its configured quorum, freshness, integrity, and confidence predicates all clear for the required evaluation window. A node MUST leave TURBO when a configured maintenance predicate fails, when freshness or integrity fails, or when InsufficientKnowledge blocks promotion. Entry and maintenance thresholds SHOULD provide hysteresis such that the maintenance threshold is no more permissive than the entry threshold. Backoff MUST be bounded. A failed confidence observation MAY cause a conservative hold or transition, but it MUST NOT be silently counted as cryptographic failure. Recovery MUST require fresh evidence and a configured dwell or consecutive-success condition. Jorgen Expires 2 April 2027 [Page 8] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 An independent L4 traffic controller, including an XDP/eBPF packet- rate controller, MUST NOT directly trigger or set AdaptiveSwitch mode. AdaptiveSwitch inputs MUST be limited to the predicates defined by this profile over current, authenticated, generation-bound evidence; packet counters, BPF-map limits, source-IP distributions, and L4 traffic-entropy values are not Confidence evidence and MUST NOT be substituted for quorum, G-Score, von Neumann, or Epi results. 14. Confidence Outcomes and Composed Decision Order Confidence outcomes are distinct from core integrity outcomes. InsufficientKnowledge indicates that enabled evidence predicates do not justify the requested action; it is not an authentication failure. It normally withholds promotion or commit as HOLD. Missing mandatory evidence may yield UNVERIFIABLE, while a verified contradiction or integrity failure yields REJECT. AdaptiveSwitch selects an operating mode and is not an admission disposition. FULL or TURBO MUST NOT by itself produce ACCEPT. The implementation MUST evaluate core integrity and replay; context binding and physical applicability when selected; provenance collapse and effective quorum; aligned peer aggregation; G-Score and optional VN; Epi qualification; then the PolicyEvaluator and a new append-only receipt. An earlier REJECT, HOLD, or UNVERIFIABLE result MUST NOT be silently promoted by a later layer. 15. Evidence and Implementation Boundary The Confidence track remains a separate companion specification. The integrated research article is one paper deposited on multiple platforms; its SSRN record is abstract 7487038 [DEEPSPACEPAPER]. The V1 Confidence work already introduced G-Score, correlation-aware von Neumann analysis, Epi qualification, AdaptiveSwitch, and a reported Rust commit boundary. This document narrows their input, authority, and evidence contracts; it does not claim those concepts as new or claim that V9 independently reproduced the prior production path. For G-Score, the current companion rule is n = 1 implies G = 0, consistent with the Deep-space companion. Quorum insufficiency is a separate predicate: N_eff below the configured quorum yields HOLD or InsufficientKnowledge even when G = 0. The V9 paper identifies a prior singleton G = 1 result as superseded and nonconformant. Historical C01-C24/26-of-26 summaries are retained as reported history only; their raw per-case outputs and run manifest were unavailable to establish that they exercised the current immutable- snapshot contract. They are not a current-suite PASS. Jorgen Expires 2 April 2027 [Page 9] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 The paper also preserves separate historical A0-A5 challenge summaries: one reports 200,000 synthetic cases with cumulative false- accept counts A0 103,774, A1 84,240, A2 63,313, A3 41,678, A4 20,236, and A5 0; another reports a separate 100,000-case cohort with rates 96.31%, 78.22%, 58.72%, 38.26%, 18.79%, and 0%, respectively. The denominators and raw challenge labels are not reconciled. These cohorts MUST remain separate reported history, MUST NOT be averaged or treated as current operational error rates, and do not establish current-profile performance. The V9 paper's C01-C24 table maps the V4 reference status to run TTTPS-DSV4-REF-20260926-R1 under validation/v4-reference-run- 20260926/; these artifacts are cited by the paper but are not bundled with this Internet-Draft. It reports C01 tested on 31,000 seeded simplex cases, C02 reference-tested for n=1 and separate quorum disposition, C03 tested with five strict-threshold probes, C05 tested on 4,000 random PSD operators with maximum diagonal VN/Shannon discrepancy 8.9 x 10^-16 bits, C14 partial (inequality checks without feasible-set optimization), and C20/C23 partial abstract-state checks. The remaining C04, C06-C13, C15-C19, C21-C22, and C24 properties are marked not tested in that packaged run. These are paper-reported statuses; the historical 26/26 summary does not replace them. The V9 paper reports six CVXPY/SCS linear-support optimization programs over positive-semidefinite trace-one bundles at dimensions 4, 8, and 12; all reported optimal status, minimum eigenvalue no lower than -2.08 x 10^-8, and trace error no greater than 5.68 x 10^- 11. It separately reports one 4 by 4 maximum-von-Neumann-entropy solve: SCS status optimal after 900 iterations, upper endpoint 1.95094 bits, minimum eigenvalue 0.16474, trace error 2.44 x 10^-6, and maximum constraint residual 0.02000120 with declared slack 0.02. This is one finite synthetic maximum-entropy endpoint. It is not a minimum endpoint, complete entropy interval, identity-diameter result, general production Epi result, or PolicyEvaluator/veto execution. A separate higher-dimensional relative-entropy sweep had no finalized result and is excluded. The paper distinguishes the Confidence Epi analyzer from the XDP packet-entropy controller shipped in @helm-protocol/ttt-mcp@0.4.7. The latter's executed script used mocked BPF-map fixtures to adjust packet-rate limits; it is not a von Neumann/Epi density-operator calculation and does not test this document's PolicyEvaluator veto. The Confidence V1 manuscript's Rust production-veto description remains prior project evidence; the V9 run did not build or invoke that production commit hook. This boundary does not assert that the production implementation is absent. Jorgen Expires 2 April 2027 [Page 10] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 The paper reports K = 3 and a 90-second dwell only as an AdaptiveSwitch boundary fixture: FULL at 89 seconds and eligible to promote at 90 seconds if all required observations remain acceptable. These values are not protocol constants or evidence of a deployed FSM run. The D3 figures in the integrated paper are isolated synthetic calibration results and remain a shadow diagnostic; they do not establish operational admission performance or enter the current reference run. Every result MUST be tied to its actual source revision, frozen inputs, policy, run identity, and evidence class. Hardware, flight, live interplanetary operation, and independent external reproduction are not established by these Confidence results. The packet-level controller evidence is separate from this Confidence profile. In the inspected source snapshot openttt-mcp@e60bae0, the IPv4 TCP XDP program handles destination ports 8443 and 8090, uses aggregate port and source-IP buckets, and can return XDP_DROP when a configured packet window is exceeded; generic-XDP and systemd deployment units are present. The packaged packet-Epi script was executed with mocked BPF-map fixtures: 12,000 packets from one source produced 0.0 bits and a 5,000-packet ceiling; 24,000 packets from four equally represented sources produced 2.0 bits and a 20,000-packet ceiling. These results exercise the L4 controller branch and mock map updates only. The operator separately reports canary revision c5f7bda attached in generic XDP mode on ens4 with systemd active. These are source-observed, mock-tested, and deployment-reported claims, respectively. The preserved package contains no live flood/DDoS kernel-load artifact, so live flood-load effectiveness is NOT MEASURED. These results do not test this draft's Confidence snapshot, G-Score/VN/Epi computation, AdaptiveSwitch, or PolicyEvaluator veto. 16. Security Considerations Colluding labels can inflate a marginal agreement distribution when provenance is not collapsed. Implementations SHOULD collapse effective identities before quorum and confidence calculation. The mapping is an authority input, not something G-Score can infer from a label. Sybil resistance is a provenance and admission property, not an entropy-only property. Before constructing p or rho, an implementation SHOULD validate D-chain freshness and collapse labels to an effective identity and provenance group. A fresh key MUST NOT increase the effective quorum merely because it has a valid signature. Let N_eff be the number of admitted unique provenance Jorgen Expires 2 April 2027 [Page 11] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 groups; quorum and Byzantine aggregation MUST use N_eff, not the raw label count. If N_eff is below policy, the result is HOLD or InsufficientKnowledge. This bounds the claimed defense to the declared identity and provenance authority; it does not prove universal Sybil prevention. Confidence thresholds can become denial-of-service controls. Implementations SHOULD bound backoff, expose HOLD and UNKNOWN states, and preserve a recovery path based on fresh evidence. A confidence result MUST NOT authorize a record that fails integrity, freshness, or admission. L4 packet-source Shannon entropy is an unauthenticated network traffic-distribution heuristic. It MUST NOT be conflated with or substituted for the Confidence profile G-Score, correlation-aware von Neumann result, Epi-Entropy, or authenticated evidence snapshot. It does not establish source identity, peer independence, oracle agreement, or state-space ambiguity. An L4 rate-limit decision is an independent network-governance action and MUST NOT be interpreted as an AdaptiveSwitch transition, confidence disposition, or PolicyEvaluator veto. Packets discarded by a pre-parser ingress filter, including XDP_DROP, do not enter the TTTPS verification state machine and MUST NOT generate a TTTPS disposition, reason code, confidence receipt, or verification receipt. If a required peer observation is absent and the resulting N_eff is below the configured quorum, the applicable profile yields HOLD or InsufficientKnowledge; the absence alone is not evidence of invalid authentication or a failed signature. 17. IANA Considerations This document makes no IANA request. It defines no wire field, codepoint, registry, or mandatory algorithm. 18. Normative References [RFC2119] Bradner, S., "Key words for use in RFCs to Indicate Requirement Levels", BCP 14, RFC 2119, March 1997, . [RFC8174] Leiba, B., "Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words", BCP 14, RFC 8174, May 2017, . 19. Informative References Jorgen Expires 2 April 2027 [Page 12] Internet-Draft Oracle Confidence Gating for TTTPS September 2026 [TTTPS] Jorgen, H., "The TLS TimeToken Secure Protocol (tttps://)", Work in Progress, Internet-Draft, draft- helmprotocol-tttps-11, . [DEEPSPACE] Jorgen, H., "TTTPS Deep-space Profile", Work in Progress, Internet-Draft, draft-helmprotocol-deepspace-02, 2026, . [DEEPSPACEPAPER] Jorgen, H., "Interplanetary Time Attestation Under Light- Time Delay", SSRN 7487038, 2026, . Author's Address Heime Jorgen Independent Email: heime.jorgen@proton.me Jorgen Expires 2 April 2027 [Page 13]